<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Static-Analysis on CuraSec</title><link>https://curasec.metacog.co.kr/tags/static-analysis/</link><description>Recent content in Static-Analysis on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 13:10:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/static-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>ARQ: LLM-based framework auto-refines CodeQL queries for C/C++</title><link>https://curasec.metacog.co.kr/insights/2026-08-24-arq-agentic-codeql-query-refinement-for-c-c-vulnerability-de/</link><pubDate>Mon, 24 Aug 2026 13:10:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-24-arq-agentic-codeql-query-refinement-for-c-c-vulnerability-de/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research showing an LLM-driven refinement loop can cut false positives and grow true positive rates by up to ~120% in CodeQL C/C++ queries without labeled datasets — worth tracking if your AppSec pipeline relies on CodeQL, but no action needed on running systems today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>LLM + Code Slicing for NFT Smart Contract Vulnerability Detection</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-ethereum-nft-smart-contracts-knowledge-guided-vulnerability/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-ethereum-nft-smart-contracts-knowledge-guided-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Interesting research combining code slicing with LLM analysis to detect reentrancy and overflow in ERC-721 contracts, but no tooling release or actionable change to running systems today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Malaika: LLM Multi-Agent Framework for Android Malware Behavior Analysis</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic research on grounded agentic reasoning for malware behavior reconstruction; no immediate engineering action, but the tri-grounding approach (domain, semantics, knowledge) is worth noting when evaluating LLM-assisted code-analysis tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Malaika&amp;rsquo;s behavior-reconstruction framing — connecting sparse program evidence to auditable behavioral conclusions — could inform how teams structure LLM-assisted malware triage workflows, though no detection or hunt action is available from this paper alone.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Tsetlin Machine Framework for Interpretable PDF Malware Detection</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-leveraging-interpretable-tsetlin-machine-for-pdf-malware-det/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-leveraging-interpretable-tsetlin-machine-for-pdf-malware-det/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic proposal for interpretable static PDF analysis using Tsetlin Machines; no tooling released or integrated into common pipelines, but the interpretability angle is worth tracking for teams building or evaluating ML-based malware classifiers.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The interpretability feature could eventually improve analyst trust in ML-based PDF triage, but no detection rules, IOCs, or deployable tooling accompany this research paper.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>